W3C home > Mailing lists > Public > public-webappsec@w3.org > September 2015

Re: CSP3 as a polylithic set of modules?

From: Brian Smith <brian@briansmith.org>
Date: Mon, 28 Sep 2015 12:08:25 -1000
Message-ID: <CAFewVt5Rde97Ma95utSABA=zNNvx687duKT1uG2=CyqAXiEpGg@mail.gmail.com>
To: Joel Weinberger <jww@chromium.org>
Cc: Mike West <mkwst@google.com>, "public-webappsec@w3.org" <public-webappsec@w3.org>, Brad Hill <hillbrad@gmail.com>, Dan Veditz <dveditz@mozilla.com>, Mark Nottingham <mnot@mnot.net>, Travis Leithead <Travis.Leithead@microsoft.com>
On Mon, Sep 28, 2015 at 11:44 AM, Joel Weinberger <jww@chromium.org> wrote:

> While I like the maintainability of this proposal, it seems like it might
> complicated the versioning that Dev has proposed in the past (that I really
> like). Namely, for each sub-spec, you'd have to tie it into a specific CSP
> version you'd like it to be in, and tracking all of that information down
> across specs might be difficult. But if we want versioning, maybe it's
> still worth figuring out how to do it well across distributed chunks like
> this.
>

I see Mike's proposal as a way towards avoiding versioning. I think it is
worth trying to avoid versioning. It's not clear what issues that people
are proposing to solve with versioning, though.

Cheers,
Brian
Received on Monday, 28 September 2015 22:08:52 UTC

This archive was generated by hypermail 2.3.1 : Monday, 23 October 2017 14:54:15 UTC